GHSA-pm7q-rjjx-979p

Suggest an improvement
Source
https://github.com/advisories/GHSA-pm7q-rjjx-979p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-pm7q-rjjx-979p/GHSA-pm7q-rjjx-979p.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-pm7q-rjjx-979p
Aliases
Published
2026-04-14T23:14:38Z
Modified
2026-06-25T23:11:41Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Oxia exposes bearer token in debug log messages on authentication failure
Details

Summary

When OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system.

Impact

An attacker with access to application logs (e.g., via a compromised log aggregation pipeline, shared logging infrastructure, or misconfigured log access controls) can extract valid JWT tokens and replay them to authenticate as legitimate users.

All versions using OIDC authentication are affected.

Details

In oxiad/common/rpc/auth/interceptor.go, the validateTokenWithContext() function logs the complete token value via slog.String("token", token) when authentication fails. This includes the full JWT header, payload, and signature.

Patches

Fixed by redacting the token in log output — only the last 8 characters are preserved for correlation purposes.

Workarounds

Ensure DEBUG-level logging is never enabled in production environments.

Database specific
{
    "cwe_ids": [
        "CWE-532"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-14T23:14:38Z",
    "nvd_published_at": "2026-04-21T22:16:20Z",
    "severity": "HIGH"
}
References

Affected packages

Go / github.com/oxia-db/oxia

Package

Name
github.com/oxia-db/oxia
View open source insights on deps.dev
Purl
pkg:golang/github.com/oxia-db/oxia

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.16.2

Database specific

last_known_affected_version_range
"<= 0.16.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-pm7q-rjjx-979p/GHSA-pm7q-rjjx-979p.json"